Business Associate Agreement

Document version — Last updated: April 14, 2026
This Business Associate Agreement (“BAA”) supplements and is incorporated into the agreement between the parties governing use of the TailoredGRC services (the “Agreement”). Capitalized terms used but not defined herein have the meanings set forth in the HIPAA Regulations (as defined below) or the Agreement.

Business Associate: TailoredGRC
Covered Entity: [Customer Company Name]
Effective Date: [Date]

1. Definitions

Unless otherwise defined herein, terms have the meanings ascribed in 45 CFR §160.103 and the HIPAA Regulations, including:

2. Obligations of Business Associate

Business Associate agrees to the following:

3. Permitted Uses and Disclosures

Business Associate may use and disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the Agreement, provided that such use or disclosure would not violate the Privacy Rule if done by Covered Entity (or is otherwise permitted under the HIPAA Regulations for business associates).

Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, and may disclose PHI for such purposes if the disclosure is Required By Law or if Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and be used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and the recipient notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.

Business Associate may de-identify PHI in accordance with 45 CFR §164.514(b) in connection with providing the Services, where permitted under the Agreement.

4. Obligations of Covered Entity

Covered Entity agrees to:

5. Security Requirements

Business Associate will implement safeguards appropriate to the size, complexity, and nature of the Services and the volume and sensitivity of ePHI, consistent with the requirements of the HIPAA Security Rule (45 CFR Part 164 Subpart C), including administrative safeguards (security management process, workforce security, information access management, security awareness and training, contingency plan, evaluation, and business associate contracts), physical safeguards (facility access controls, workstation use, device and media controls), and technical safeguards (access control, audit controls, integrity, person or entity authentication, and transmission security).

Covered Entity is responsible for configuring access credentials, assigning roles, and managing end-user devices and networks outside Business Associate’s control in accordance with Covered Entity’s policies and applicable law.

6. Breach Notification

Upon discovery of a breach of unsecured PHI as defined in 45 CFR §164.402, Business Associate will notify Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery, in accordance with 45 CFR §164.410. The notification will include, to the extent known, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach, and such other content as required by 45 CFR §164.410(c).

Covered Entity remains responsible for notifying affected individuals, the Secretary, and, where applicable, the media, in accordance with 45 CFR §164.404–§164.408.

7. Term and Termination

This BAA becomes effective on the Effective Date and continues until terminated as set forth herein or in the Agreement.

Either party may terminate this BAA and the underlying Agreement as permitted by the Agreement. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity may provide an opportunity for Business Associate to cure the breach, and may terminate this BAA and the Agreement if cure is not feasible or is not timely accomplished, as permitted under 45 CFR §164.504(e)(2)(iii).

8. Return or Destruction of PHI upon Termination

Upon termination of this BAA for any reason, Business Associate will, at the option of Covered Entity, return or destroy all PHI maintained by Business Associate in any form and retain no copies of such information, or, if return or destruction is infeasible, extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, in accordance with 45 CFR §164.504(e)(2)(ii).

Business Associate will document disposal or return in a manner consistent with its policies and applicable law.

9. Miscellaneous

Amendment

This BAA may be amended only in a writing signed by both parties, except that Business Associate may update non-material administrative provisions in posted templates when required to align with changes in law, with reasonable notice to Covered Entity.

Waiver

No waiver of any provision of this BAA will be effective unless in writing. Failure to enforce any provision is not a waiver of future enforcement.

Governing Law

This BAA is governed by the laws of the State of Missouri, without regard to conflict-of-law principles, except to the extent superseded by federal law.

Interpretation

Any ambiguity in this BAA will be resolved to permit Covered Entity and Business Associate to comply with the HIPAA Regulations.

10. Signatures

By signing below, the parties agree to be bound by this BAA as of the Effective Date.

Covered Entity

[Customer Company Name]

Signature

Print name & title

Date

Business Associate

TailoredGRC

Signature

Print name & title

Date

Questions regarding this BAA: btaylor@tailoredgrc.com